77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
ISO 27001 Implementation Consulting in Berlin: A Buyer's Guide for 2026
IT-Sicherheit & NIS-2

ISO 27001 Implementation Consulting in Berlin: A Buyer's Guide for 2026

7 August 202613 min readBy Lena Vogt
CIVAC

Choosing an ISO 27001 implementation consultant in Berlin: scope, deliverables, timelines, costs, and the difference between a consultant who runs the project and one who hands you a templated PDF.

The October 2025 deadline for transitioning legacy ISO/IEC 27001:2013 certificates to the 2022 revision has come and gone. From October 2026 onwards, only ISO/IEC 27001:2022 is recognised by accredited certification bodies in Germany. Berlin-based organisations seeking certification, whether for procurement reasons, customer contracts, BaFin requirements, or NIS-2 alignment, now face two questions in parallel: which consulting partner to engage, and which certification body to book. Both decisions affect timeline, cost, and audit outcome, and both deserve more diligence than the average vendor selection.

This guide explains how to evaluate ISO 27001 implementation consultants in the Berlin market. You will find the typical project structure, realistic timelines, cost bands for organisations with 50 to 500 employees, and a clear view of the 93 Annex A controls grouped into the four themes of the 2022 revision. You will also see where consulting projects go wrong and how to avoid these patterns. CIVAC is a compliance platform and Officer-as-a-Service operating from Berlin and Munich, with 25 officer roles, 490 audit-ready templates, and an ISMS infrastructure that is itself ISO/IEC 27001:2022 certified and hosted in EU data residency.

Auf einen Blick

  • An ISO 27001:2022 implementation project in Berlin typically takes nine to twelve months from kickoff to certificate, with consulting effort concentrated in months one through six.
  • Choose between a consulting partner who runs the project end-to-end and one who delivers templates only; the price difference is real but so is the audit outcome.
  • The 2022 revision groups 93 Annex A controls into four themes (organisational, people, physical, technological) and adds eleven new controls that legacy ISMS environments must close before recertification.

What ISO 27001 implementation consulting actually covers

Implementation consulting for ISO/IEC 27001:2022 is more than a checklist exercise. A serious project covers seven activities. First, scope definition: identifying which business units, locations, products, and information assets are inside the Information Security Management System (ISMS) and which are explicitly excluded. A scope that is too broad inflates audit cost; a scope that is too narrow exposes commercial gaps. Second, gap analysis against the standard's clauses 4 to 10 and against the 93 Annex A controls in their 2022 grouping. Third, risk assessment using a documented methodology such as ISO/IEC 27005 or a structured equivalent. Fourth, statement of applicability (SoA) that documents which controls are in scope, which are excluded, and why.

Fifth, policy and procedure design covering at minimum information security policy, access management, supplier security, business continuity, incident response, secure development, and cryptographic controls. Sixth, evidence collection and operational implementation, including running each control through at least one cycle so that the audit can verify operating effectiveness. Seventh, internal audit and management review prior to the certification audit. A consultant who skips any of these activities is delivering documentation, not an implementation. The CIVAC briefing on the 2022 transition describes the specific deltas between the 2013 and 2022 revisions, which is the starting point for any gap analysis in Berlin organisations still operating under legacy certificates. A consultant who cannot articulate these deltas in the first conversation is unlikely to manage them well in the project. The same applies to the relationship between the ISMS and other compliance frameworks: NIS-2, DORA, BAIT, VAIT, and TISAX often overlap with ISO 27001, and a competent partner will surface these overlaps in scoping rather than treating each framework in isolation.

The Berlin market: consultants, certification bodies, accreditations

Berlin has one of the densest concentrations of ISO 27001 consultants in Germany, driven by the local tech and SaaS ecosystem, FinTech, GovTech, and the public sector. Consultants in this market range from individual practitioners charging EUR 1.200 to EUR 1.800 per day, to mid-sized firms charging EUR 1.500 to EUR 2.200 per day, to international advisory firms charging EUR 2.500 to EUR 4.000 per day. The price difference reflects team depth, methodology maturity, and the willingness to take operational responsibility, not just documentation responsibility. A solo practitioner can run a project for a 30-person SaaS company; a 500-person organisation with multiple sites needs structured team capacity.

Certification bodies operating in Berlin include TUV Sud, TUV Rheinland, TUV Nord, DEKRA, DQS, BSI Group, LRQA, and SGS, all accredited by DAkkS (Deutsche Akkreditierungsstelle). The accreditation matters: certificates from non-DAkkS-accredited bodies may be rejected by customers in regulated industries. Cost for the two-stage audit (Stage 1 documentation review plus Stage 2 implementation audit) ranges from EUR 8.000 to EUR 25.000 in year one depending on scope and headcount, plus annual surveillance audits of EUR 4.000 to EUR 10.000. A reasonable consulting engagement separates consulting fees from audit fees and discloses both transparently. Beware bundled offers that obscure the audit cost; the certification body must be independent of the consultant, and a single invoice often signals a problem.

Project timeline: nine to twelve months from kickoff to certificate

A realistic ISO 27001:2022 implementation in a Berlin organisation with 50 to 250 employees takes nine to twelve months. Compressed timelines of six months exist but require dedicated internal capacity, a mature security baseline, and significant management attention; they are the exception, not the rule. The standard project structure has four phases. Phase one (months one to two): scope definition, asset inventory, gap analysis, initial risk assessment. Phase two (months three to five): policy and procedure design, control implementation, training, supplier security review. Phase three (months six to eight): operational evidence collection, internal audit, management review, remediation of internal findings.

Phase four (months nine to twelve): Stage 1 audit by the certification body, remediation, Stage 2 audit, certificate issuance. The Stage 1 audit is a documentation review; the Stage 2 audit checks operating effectiveness on site or remotely. A common Berlin pattern: companies underestimate the operational evidence collection in phase three and find themselves rushing to generate logs, tickets, and meeting minutes ahead of Stage 2. Consultants who push back on unrealistic timelines protect their clients; those who promise certificates in five months are usually selling a templated PDF. The dual-model frame applies here: license the workspace for your internal ISO project lead, or have CIVAC officers run the project. The first is faster for organisations with internal capacity; the second is faster for organisations without. A blended pattern also works: an internal coordinator handles day-to-day project management while an external Information Security Officer takes formal responsibility for the ISMS and signs the relevant policies.

The 93 Annex A controls: themes, deltas, prioritisation

ISO/IEC 27001:2022 groups its 93 Annex A controls into four themes: organisational (37 controls), people (8 controls), physical (14 controls), and technological (34 controls). The 2013 revision had 114 controls in 14 categories; the 2022 revision consolidates and adds eleven new controls. The new controls reflect the security landscape of 2026: threat intelligence (A.5.7), information security for cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).

For Berlin organisations transitioning from 2013, the eleven new controls are the priority. Threat intelligence (A.5.7) is often the most operationally challenging because it requires a documented intake of external threat data with periodic review. Cloud security (A.5.23) is straightforward conceptually but requires explicit supplier contracts and shared-responsibility documentation. Secure coding (A.8.28) demands evidence from development pipelines, including code review, dependency scanning, and secret management. A consultant who knows the 2022 deltas will start with these eleven controls and use them as the structural scaffold for the engagement; one who treats the standard as a flat checklist will miss the prioritisation that makes the difference between a clean certificate and a list of nonconformities. The eleven new controls also map onto common NIS-2 requirements, which means a well-structured 2022 implementation reduces the marginal cost of NIS-2 compliance later on.

Stage 1 and Stage 2: what the certification audit actually examines

The Stage 1 audit examines documentation. The auditor reviews the ISMS scope, the information security policy, the statement of applicability, the risk assessment methodology, the risk treatment plan, the internal audit programme, and management review records. Stage 1 typically takes one day for small organisations and two to three days for larger scopes. Common Stage 1 findings: SoA inconsistent with risk assessment, missing approvals on policies, internal audit programme not yet executed, management review missing required inputs (clause 9.3.2). A well-prepared organisation passes Stage 1 with zero major nonconformities and a small list of observations.

The Stage 2 audit examines operating effectiveness. The auditor selects a sample of controls and tests them through interviews, document inspection, log review, and walkthrough of processes. For technological controls, the auditor will request screenshots, log exports, ticket histories, and configuration files. For organisational controls, the auditor will request meeting minutes, training records, incident logs, and supplier assessments. Stage 2 typically takes two to five days, depending on scope. Major nonconformities at Stage 2 require remediation within 90 days and may delay certificate issuance. A robust internal audit programme catches most issues before Stage 2 and reduces the audit risk substantially. The auditor's role is not to test every control exhaustively but to gather sufficient evidence that the ISMS works as documented, which is why an audit-fest, documented system survives much better than a documented-only system. Surveillance audits in years two and three follow the same logic but sample fewer controls, which means the operational maturity established in the first year compounds across the certification cycle.

Costs: realistic budgets for Berlin organisations

A 50-employee Berlin SaaS company can expect consulting costs of EUR 25.000 to EUR 50.000 for end-to-end implementation, plus EUR 8.000 to EUR 12.000 for the Stage 1 and Stage 2 audit. Annual surveillance audits add EUR 4.000 to EUR 6.000. Recertification every three years repeats the Stage 1 and Stage 2 effort at slightly reduced scope. A 250-employee company sees consulting costs of EUR 60.000 to EUR 120.000 and audit fees of EUR 15.000 to EUR 25.000. A 500-employee company with multiple sites can budget EUR 150.000 to EUR 300.000 for the initial implementation. These ranges assume a single ISMS scope; multiple scopes or country-specific certificates multiply the cost.

Internal cost is the often-overlooked factor. The internal project lead spends 30 to 50 percent of their time on the ISMS during implementation; key control owners across IT, HR, legal, and operations spend 5 to 15 percent of their time. Add the cost of training, tooling (GRC platform, vulnerability scanner, SIEM if not already in place), and any infrastructure changes required to close control gaps. A realistic total cost of ownership for a 100-employee company is EUR 80.000 to EUR 150.000 in year one and EUR 30.000 to EUR 50.000 in subsequent years. Cheaper offers exist, but they typically transfer hidden cost to the internal team and risk a longer or failed audit. The cost picture changes when the consulting partner can also provide the long-term Information Security Officer function as an ongoing service, which compresses both setup time and steady-state cost.

How to evaluate a consulting partner: ten diagnostic questions

Ten questions separate serious consultants from documentation vendors. First: how many ISO/IEC 27001:2022 audits has your team supported in the last twelve months, with which certification bodies? A consultant unfamiliar with TUV Sud and DEKRA in Berlin is a red flag. Second: who is the named partner on this engagement, and what is their backup? Avoid bait-and-switch where a senior sells the deal and a junior delivers it. Third: do you provide the GRC tooling, or do we license our own? A bundled platform can reduce friction but may create lock-in. Fourth: how do you handle the eleven new 2022 controls in our context? The answer should reference specific controls, not generic language.

Fifth: what evidence do you take responsibility for collecting, and what stays with us? Sixth: how do you support the internal audit and management review? Seventh: what is your approach when we disagree with a control implementation? Eighth: how do you handle Stage 1 findings between Stage 1 and Stage 2? Ninth: can you provide three references from comparable Berlin organisations and one from a project that did not certify on first attempt? Tenth: how do you transition from implementation to ongoing operations? The last question matters most: an ISMS is not a project but a permanent organisational function, and the consultant who hands you the certificate and walks away has left you with a maintenance problem. Bestellurkunde, unterschrieben, abgelegt, belegbar applies just as much to the Information Security Officer as to any other officer role.

From certificate to operations: the steady-state ISMS

The certificate is the start, not the end. An ISMS in operation requires monthly risk register updates, quarterly internal audits of selected controls, semi-annual management reviews, annual policy reviews, ongoing supplier security assessments, continuous awareness training, incident response readiness, and surveillance audit preparation. The Information Security Officer (ISB in German) coordinates these activities and reports to the management board. For NIS-2 in-scope organisations, the ISB role also includes the 24-hour early warning and 72-hour follow-up reporting to BSI under § 32 BSIG, which adds an operational dimension that the ISMS alone does not cover but that the ISB is expected to handle in parallel.

This is where the dual-model frame becomes operationally relevant. License the workspace for your internal Information Security Officer, or have a CIVAC officer take on the role. The first works when you have a dedicated full-time ISB; the second works when the role is too narrow for full-time but too critical to leave to ad-hoc effort. The CIVAC SLA of two business days for initial onboarding compresses the typical four-to-six-week gap between deciding to staff the role and actually having someone in place. The workspace includes 490 audit-ready templates covering risk register, statement of applicability, internal audit programme, management review minutes, supplier security assessment, incident response runbook, and surveillance audit preparation. Andere führen Compliance wie einen Aktenschrank. Wir führen sie wie Software, even when the article is written in formal English.

From reading to a structured engagement

Selecting an ISO/IEC 27001:2022 implementation consultant in Berlin is a decision with multi-year consequences. The standard is rigorous, the audit is genuine, the cost is meaningful, and the operational tail extends across the entire certification cycle. A consulting partner who treats this as a templated project will leave you with a brittle ISMS that survives the first certificate but struggles with the first incident or the first surveillance audit. A partner who treats it as an organisational change project, with both the documentation and the operational depth, gives you a system that grows with the business. The choice is yours, but the consequences differ by an order of magnitude.

CIVAC is a compliance platform and Officer-as-a-Service with 25 officer roles, 490 audit-ready templates, and an ISMS infrastructure that is itself ISO/IEC 27001:2022 certified, hosted in EU data residency. You have two ways forward. License the workspace for your internal officers, including Information Security Officer and Data Protection Officer, or have our officers take on the role. License the workspace for your internal officers, or have our officers be appointed. The first path gives you the templates, the workflows, and the audit-ready evidence structure for your existing team. The second path gives you an experienced ISB or DPO with a two-business-day onboarding SLA, instead of the four-to-six-week market average. Both paths converge on the same outcome: a certificate that holds, an ISMS that operates, and documentation that survives the next audit cycle. Aus dem Lesen einen Auftrag machen. Write to info@civac.de or use the contact form on our FAQ page if you would like to discuss your specific scope. We typically respond the same working day and run a 30-minute initial conversation without commitment, covering scope, timeline, and operating model.

FAQ

How long does an ISO/IEC 27001:2022 implementation take for a Berlin organisation?

A realistic implementation for a 50 to 250-employee organisation takes nine to twelve months from kickoff to certificate. Compressed six-month timelines are possible only with dedicated internal capacity, a mature baseline, and active management support. The Stage 1 and Stage 2 audits sit at the end of the timeline, with at least four to six weeks between them to allow for findings remediation if needed.

What is the difference between ISO/IEC 27001:2013 and the 2022 revision?

The 2022 revision reorganises Annex A from 114 controls in 14 categories into 93 controls in four themes (organisational, people, physical, technological) and introduces eleven new controls covering threat intelligence, cloud security, secure coding, data leakage prevention, and others. The clauses 4 to 10 remain largely unchanged. Legacy 2013 certificates expire 31 October 2026 and must transition to 2022.

How much does ISO 27001 consulting cost in Berlin?

Consulting fees for a 50-employee organisation range from EUR 25.000 to EUR 50.000; for a 250-employee organisation from EUR 60.000 to EUR 120.000. Add EUR 8.000 to EUR 25.000 for the certification audit and EUR 4.000 to EUR 10.000 annually for surveillance audits. Internal cost adds 30 to 50 percent of one full-time equivalent during implementation, often more if the security baseline is immature.

Do I need a DAkkS-accredited certification body?

For practical purposes, yes. Certificates from non-DAkkS-accredited bodies are often rejected by customers, particularly in regulated industries, public-sector procurement, and financial services. DAkkS-accredited bodies operating in Berlin include TUV Sud, TUV Rheinland, TUV Nord, DEKRA, DQS, BSI Group, LRQA, and SGS. Always verify the accreditation status of the certification body before contracting.

Can the same partner provide both consulting and the certification audit?

No. Independence between consultant and certification body is a strict requirement of ISO/IEC 17021. A single party cannot both advise on implementation and certify the ISMS. Be cautious of bundled offers; they may indicate an inappropriate relationship between consultant and audit body that could invalidate the certificate or expose your organisation in customer audits later on.

How does CIVAC support ISO 27001 implementation projects?

CIVAC provides a compliance platform with 37 audit-ready templates covering the ISMS lifecycle, plus the option to appoint an external Information Security Officer as Officer-as-a-Service. You either license the workspace for your internal team or have CIVAC officers appointed with a two-business-day onboarding SLA. Both options are designed around the 93 Annex A controls of ISO/IEC 27001:2022.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles